What Is a Managed Security Awareness and Phishing Simulation Service?
A managed security awareness service provides ongoing staff learning, phishing simulations, new-starter onboarding, reporting routes and management evidence. 39Security uses short practical campaigns and realistic phishing testing to reinforce safer behaviour throughout the year, rather than competing with a one-off instructor-led cyber security training course.
Managed Security Awareness for Small Businesses
Small businesses that want an ongoing security awareness programme for staff who handle email, payments, customer information, Microsoft 365 and remote working, especially where phishing testing, completion evidence or recurring reinforcement is required.
Why Ongoing Security Awareness Reduces Human Cyber Risk
People face changing threats and may not know how to verify an unusual request or report a mistake quickly. Generic annual videos can be forgotten, while a blame-based approach discourages early reporting. The programme builds repeatable habits and a supportive response process.
Managed Phishing Simulations and Security Awareness: What Is Included?
- Short role-relevant awareness modules
- Managed phishing simulations with safe learning feedback
- New-starter security onboarding
- Reporting and escalation guidance
- Completion and campaign reporting
- Management recommendations based on observed themes
- Recurring awareness campaigns targeted to current risk
Security Awareness Service Scope and Exclusions
- Employee surveillance or disciplinary decisions
- Guarantee that trained users will never make a mistake
- HR policy drafting beyond the agreed security scope
- Specialist regulated-sector training unless quoted
How Managed Phishing Awareness Campaigns Are Implemented
We identify user groups, higher-risk roles, current policies and common workflows. A baseline campaign is agreed, communications are prepared and the reporting method is tested. Results are used to target additional learning without publicly shaming individuals.
Security Awareness Platforms, Microsoft 365 and Phishing Testing
The managed programme is delivered through a supported security-awareness platform, with phishing simulation integration normally using Microsoft 365 or another compatible email platform. Instructor-led business training is provided separately through the cyber security training pages.
How Suspicious Email Reports and Phishing Results Are Reviewed
Reported suspicious messages and campaign indicators can be routed for technical review where email-security or managed support is included. Awareness activity itself is not a 24/7 incident-monitoring service.
How 39Security Responds to Reported Phishing and Awareness Risks
39Security helps users and managers understand the message, reinforces the correct action and escalates real incidents through the relevant email, identity or incident-response service. The client remains responsible for HR decisions and internal communications.
Employee Security Awareness Reporting and Phishing Simulation Results
Completion rates, simulation trends, reporting behaviour and recommended actions provide management evidence. Reporting should focus on improving controls and confidence rather than producing misleading league tables.
Security Awareness, Cyber Insurance and Cyber Essentials
Awareness supports governance, insurance expectations and staff responsibilities. Cyber Essentials focuses mainly on technical controls, so training is helpful but does not replace the five required control areas or independent assessment.
Managed Security Awareness and Phishing Simulation Pricing
Managed awareness pricing is normally based on users, campaign frequency and reporting requirements. Instructor-led training days and bespoke executive, finance or incident workshops are separate services with their own published or quoted pricing.
Ongoing Security Awareness Programme Governance
Before activation, the proposal should identify the covered users, devices, locations and platforms, together with the service window, escalation contacts and change responsibilities. During operation, material exceptions are recorded rather than hidden, and recommendations are separated into urgent actions, planned improvements and optional projects. This gives managers a practical view of risk, cost and ownership.
Service reviews should test whether coverage still matches the business. New starters, leavers, acquisitions, cloud applications, office moves and supplier changes can all create gaps. 39Security therefore treats onboarding, reporting and periodic review as part of the control, not as administration around the edge of the product.
What Good Managed Security Awareness Should Look Like
A buyer should be able to identify what is protected, who is watching it, what happens when something goes wrong and which evidence will be available afterwards. The provider should explain limitations honestly, avoid vague promises and document any dependency on Microsoft licensing, internet connectivity, third-party suppliers or customer action. Clear boundaries make response faster and reduce disputes during an incident.
Questions to Ask a Security Awareness Provider
- Which systems, users and locations are included in the quoted scope?
- Who reviews alerts, during which hours, and what happens when the named contact is unavailable?
- What evidence will we receive for clients, insurers, auditors or board reporting?
- Which actions are included in the monthly fee and which require separate project approval?
- How are service quality, response times, exclusions and exit arrangements documented?
Managed Security Awareness and Phishing Simulation FAQs
Does Cyber Essentials require staff training?
Cyber Essentials is centred on five technical controls and does not certify a general awareness programme. Training is still a sensible supporting measure because staff need to use MFA, report suspicious activity and follow secure business processes.
Are phishing simulations designed to catch people out?
No. A well-run simulation is a learning exercise, not a public test of intelligence. Campaigns should reflect realistic risk, provide immediate guidance and encourage users to report uncertainty quickly.
How often should training happen?
Short, repeated learning is usually more effective than one long annual session. The appropriate frequency depends on staff turnover, risk, incidents and customer requirements, with additional training for finance, administrators and senior leaders.
Do you also provide instructor-led cyber security training?
Yes. Instructor-led business training is a separate service with dedicated employee, phishing and Cyber Essentials workshop pages. The managed awareness service is designed for ongoing campaigns, phishing simulations, onboarding and reporting between formal training sessions.